Source Protection Policy
If you give us information in confidence, we protect your identity. This page describes what that means in practice and, as importantly, what we cannot promise.
What we do
We do not disclose the identity of a confidential source to anyone outside the small number of editors who need it to verify the material. We do not name a source in internal notes, drafts or correspondence. Where we describe a source in an article, the description is chosen so that it establishes standing without narrowing the field of people it could be.
Documents received in confidence are handled so that details identifying their recipient or their route to us are not reproduced. Where a document must be published to support a claim, we redact what would identify the person who provided it, and we tell you before publication.
What we cannot promise
We cannot control the systems you use to reach us. Email, web forms and telephone networks keep records we neither see nor manage. If you are contacting us about something that puts you at risk, the first message is the one most likely to expose you.
We are also subject to law. We will resist a demand to identify a source through the means available to us, but no publication can guarantee the outcome of a legal process it has not yet faced.
Getting in touch more safely
Do not use equipment or an account belonging to the organisation you are telling us about. Do not use a work network. Consider whether the fact of contacting a publication is itself the risk, separately from what you say.
Use the contact form and choose Whistleblower Tip. Tell us how you would prefer to be reached before sending anything sensitive, and we will arrange it.